Invention Grant
- Patent Title: Detecting executable code within a data entity
-
Application No.: US16157073Application Date: 2018-10-10
-
Publication No.: US10650144B2Publication Date: 2020-05-12
- Inventor: Meni Farjon , Boris Vaynberg , Yossi Sara
- Applicant: Solebit Labs, Ltd.
- Applicant Address: IL Herzliya
- Assignee: Solebit Labs Ltd.
- Current Assignee: Solebit Labs Ltd.
- Current Assignee Address: IL Herzliya
- Agency: Soquel Group I.P Ltd.
- Main IPC: G06F21/56
- IPC: G06F21/56

Abstract:
A method for protecting a computer, including receiving a data block, discovering code within the data block that can be disassembled for a machine instruction, building an execution path from the machine instructions, including parsing the machine instructions, and following the flow of the execution path, including conditional and unconditional branches of the machine instructions, validating an incremented location by scanning the execution path for machine instructions that increment a register that stores a location on the execution path, finding a self-modifying artifact by scanning remaining machine instructions in the execution path for an arithmetic or logic operation performed on a register that currently or previously held a location in the incremented location, finding a modified loop index by scanning remaining machine instructions in the execution path for registers that hold a loop value that is incremented or decremented, and blocking the data when finding the modified loop index.
Public/Granted literature
- US20190087573A1 DETECTING EXECUTABLE CODE WITHIN A DATA ENTITY Public/Granted day:2019-03-21
Information query